skill-evolution
Fail
Audited by Gen Agent Trust Hub on Aug 15, 2026
Risk Level: HIGHCOMMAND_EXECUTIONPROMPT_INJECTION
Full Analysis
- [COMMAND_EXECUTION]: The script
scripts/analyze-skill.shis vulnerable to shell and SQL injection. The variable$SKILL_IDis interpolated directly into a double-quoted string passed to thesqlite3CLI ("SELECT COUNT(*) FROM skill_metrics WHERE skill_id='$SKILL_ID';"). An attacker providing a malicious skill ID could execute arbitrary shell commands via subshells (e.g.,$(rm -rf /)) or manipulate the database through SQL injection (e.g.,'; DROP TABLE skill_metrics; --). - [PROMPT_INJECTION]: The skill implements an indirect prompt injection surface through its automated analysis and evolution logic.
- Ingestion points: External data enters the agent's context through
{project_path}and{feedback}inprompts/post-execution.md, and{trigger_reason}inprompts/evolution.md. - Boundary markers: The templates lack boundary markers or explicit instructions to treat variables as untrusted data, allowing embedded instructions in project files or feedback to influence agent behavior.
- Capability inventory: The skill possesses capabilities to modify the local filesystem (writing to
monitor.mdandevolution-log.md) and manipulate the internal database used to drive agent evolution decisions. - Sanitization: No sanitization, validation, or escaping of ingested strings is performed before they are interpolated into prompts or script arguments.
- [COMMAND_EXECUTION]: The script
scripts/report.shprogrammatically generatesmonitor.md. If a skill name or metric in the database is compromised via the aforementioned SQL injection, it can be used to inject malicious markdown content (such as deceptive links or instructions) into the monitoring dashboard, which is then served to the user or agent.
Recommendations
- AI detected serious security threats
Audit Metadata